Impact
The defect allows an attacker to upload files of any type to the web server, enabling the placement of a web shell and subsequent execution of arbitrary code. This flaw is classified as CWE-434, representing an unrestricted upload of a file with a dangerous type. The consequence is a full compromise of the site’s integrity and confidentiality.
Affected Systems
The vulnerability is present in the File Manager Plugin For Wordpress produced by getredhawkstudio and affects all released versions up to and including 7.5. WordPress installations that have not applied a newer patch are susceptible.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity. The EPSS score of less than 1% suggests a low but non-zero likelihood of exploitation at the time of analysis. The flaw is not listed in the CISA KEV catalog, yet the remote upload capability and the ease of deploying a shell make it attractive to attackers with moderate skill. Based on the description, it is inferred that the attack can be performed through the plugin’s upload interface by any user who can access that form, without requiring pre-authentication.
OpenCVE Enrichment
EUVD